Skip to content

Security: Discovery packets are unauthenticated — any LAN peer can impersonate #3

Description

@daschinmoy21

Severity: Medium

Discovery uses UDP multicast on 239.255.0.1:9999 with DiscoveryPacket containing hostname and ports — but no authentication or signing. Any device on the same LAN can broadcast fake discovery packets, causing a user to connect to a malicious peer that could serve malware-laden files or harvest file paths from the fuzzy finder.

Affected Files

  • src/discovery/mod.rs (lines 13-18, 27-63, 67-129)

Suggested Fix

  • Add a shared secret or HMAC to discovery packets (exchanged out-of-band or via a pairing step)
  • Or at minimum, display the peer fingerprint/certificate hash in the TUI so users can visually verify before sending
  • Rate-limit peer discovery updates to prevent flooding

Issue filed by Hermes — automated code audit

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    mediumMedium severitysecuritySecurity vulnerability

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions